Microsoft Entra ID cannot issue an access token for multiple audiences.
The new --entra-id-redeem-scope option (alpha config:
microsoftEntraIDConfig.redeemScope) allows requesting a broad scope list
at authorization time while sending a narrowed, single-audience scope
when exchanging the authorization code for tokens, as permitted by
RFC 6749 section 3.3. If unset, behaviour is unchanged.
Applies to both the client-secret and federated-token redemption paths
of the entra-id provider.
Fixes#2751
Signed-off-by: Mathias Mikkel Neerup <mane@tv2.dk>